b1e167d5d98b19587df1489038ad3418c1fbde0b05b50137a165062d4974d8d3

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Jun-15 02:29:20
Detected languages English - United States

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Info Interesting strings found in the binary: Contains domain names:
  • github.com
  • houseindustries.com
  • http://www.houseindustries.com
  • http://www.houseindustries.com/license
  • http://www.houseindustries.com/licenseBurbank
  • http://www.houseindustries.comhttp
  • http://www.talleming.comHouse
  • https://discord.gg
  • https://files.catbox.moe
  • https://files.catbox.moe/x7ic4m.sys
  • https://github.com
  • https://guns.lol
  • www.houseindustries.com
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
  • FindWindowA
Code injection capabilities (PowerLoader):
  • GetWindowLongA
  • FindWindowA
Possibly launches other programs:
  • CreateProcessA
  • ShellExecuteA
  • system
Uses functions commonly found in keyloggers:
  • GetForegroundWindow
  • GetAsyncKeyState
Manipulates other processes:
  • Process32Next
  • Process32First
Reads the contents of the clipboard:
  • GetClipboardData
Malicious VirusTotal score: 39/65 (Scanned on 2026-07-20 11:21:29) ALYac: Gen:Variant.Yogi.17658
APEX: Malicious
AhnLab-V3: Malware/Win.GameHack.C5905125
Antiy-AVL: Trojan/Win32.Agent
Arcabit: Trojan.Yogi.D44FA
Avira: TR/W64.Agent
BitDefender: Gen:Variant.Yogi.17658
Bkav: W32.Malware.CB94459B
CTX: exe.trojan.generic
CrowdStrike: win/malicious_confidence_90% (D)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DrWeb: Trojan.Siggen32.59326
ESET-NOD32: Win64/GenKryptik.HSTQ trojan
Elastic: malicious (high confidence)
Emsisoft: Gen:Variant.Yogi.17658 (B)
F-Secure: Trojan.TR/W64.Agent
Fortinet: Adware/GameHack_AGen
GData: Gen:Variant.Yogi.17658
Google: Detected
Malwarebytes: Malware.AI.3776532247
MaxSecure: Trojan.Malware.324995110.susgen
McAfeeD: Trojan:Script/Redcap.EAB
MicroWorld-eScan: Gen:Variant.Yogi.17658
Microsoft: Trojan:Win32/Kepavll!rfn
Paloalto: generic.ml
Rising: Trojan.Kryptik!8.8 (TFE:5:oW1CcedgyWF)
Sangfor: Trojan.Win64.Kryptik.Vbtb
SentinelOne: Static AI - Suspicious PE
Skyhigh: BehavesLike.Win64.Dropper.jh
Sophos: Mal/Generic-S
Symantec: ML.Attribute.HighConfidence
Tencent: Malware.Win32.Gencirc.14b1fc1c
TrellixENS: Artemis!2F8B95EC0507
TrendMicro: Trojan.Win32.ZYX.USBLFK26
TrendMicro-HouseCall: Trojan.Win32.ZYX.USBLFK26
VIPRE: Gen:Variant.Yogi.17658
Varist: W64/ABApplication.BEXU-6645
alibabacloud: Trojan:Win/Kepavll.Gen

Hashes

MD5 2f8b95ec05075e67745c48a744ce39bf
SHA1 f0ef36cb20d740d3ce002339432cb119603c24cd
SHA256 b1e167d5d98b19587df1489038ad3418c1fbde0b05b50137a165062d4974d8d3
SHA3 97db63f9e14933fb47a4a7f3fe438451640d36a42b3c4b749bac327f91a13e3e
SSDeep 12288:NRfm0RqZY+NbxB1BzJiTnodhyC6YLK2eooFn:jfmnZYADdiTnodh+YW2i
Imports Hash 3e4d7cef6da689923911c6fbac452b6a

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf0

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2026-Jun-15 02:29:20
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x52600
SizeOfInitializedData 0x4a800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000051F10 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0xa1000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 4c49d0ee1c5163d79c61fed9469d3505
SHA1 2469bba484dffb6316a7add7423e43290f628dbb
SHA256 8ef918ae85a72f7cc40010e55498ae0bc03b711c94de7d8f665650fa72460a26
SHA3 235d7db53ad891b3d584040bfcd4b3048b90358b1590b18799ef9ce364c315ef
VirtualSize 0x52440
VirtualAddress 0x1000
SizeOfRawData 0x52600
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4998

.rdata

MD5 79bdd89adee51f78c2609658ded573a9
SHA1 0d9c294320f7b8902cd806a2ba93e7da26d504e0
SHA256 720547f8fb78e9380917ad514e2690e5312123c34451e7ea2df73cafe941aab0
SHA3 9c1d08c79e656f5f6d495b0aea5be3d8f82dc88a5438e26bc7ae57bb65be2ee4
VirtualSize 0x11ace
VirtualAddress 0x54000
SizeOfRawData 0x11c00
PointerToRawData 0x52a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.0177

.data

MD5 eefe8bb42e4dc7776a127f112c0e9707
SHA1 280c7b4ca529ee5db564dc999bcb8b455180c8b7
SHA256 e41fd48b223af3354ea52e2bae161f84553da3b98239969028224731b5ce38af
SHA3 12fa71b42fd15f8de8f670c5aff65422a0a4840b8c9d98667b88012895bcfe96
VirtualSize 0x34df8
VirtualAddress 0x66000
SizeOfRawData 0x34c00
PointerToRawData 0x64600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 6.87616

.pdata

MD5 15a1ab76ebb05602e927facbbd4edf60
SHA1 0fb2707e4271959d1e2644f3bbfeca51009cb62f
SHA256 6cf6ed2d6eec66b4d2f3a3300db38e246a5cccd073630cc8a8517dc156306c8c
SHA3 3600cc9358f2d8ac09aa538a19daddb820965eee37ca204a6ddfc094b5a60e96
VirtualSize 0x3720
VirtualAddress 0x9b000
SizeOfRawData 0x3800
PointerToRawData 0x99200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.75503

.rsrc

MD5 cf6491a7a9b8f84ff2f9ae2315f664c7
SHA1 ba80417924364ac3001acd7bf85a52f67db06869
SHA256 7661c23566bccb89d9771b10e9997ffa4ec87d5101f79929b203c1dd3529ab72
SHA3 4b5688b35498782ef0c3536603252c092f9d8206b1a9a91f2fcfe3aca1f29170
VirtualSize 0x1e0
VirtualAddress 0x9f000
SizeOfRawData 0x200
PointerToRawData 0x9ca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.71377

.reloc

MD5 6dab50120cd9bdf533cfc7c7038a072a
SHA1 696819a3ac3309729b20a96f34bfe137de2947d3
SHA256 31735206f5b79636d39a925cf7a96b9bbca05efb12df0e61f98184cb4b737c72
SHA3 becfa847f1e02265e33becdcf5c9288f936bb845b7bbcee7071ad795945f789b
VirtualSize 0x238
VirtualAddress 0xa0000
SizeOfRawData 0x400
PointerToRawData 0x9cc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 3.57739

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
dwmapi.dll DwmExtendFrameIntoClientArea
KERNEL32.dll SetConsoleTitleA
GetStdHandle
DeviceIoControl
WaitForSingleObject
CreateFileW
CreateToolhelp32Snapshot
Sleep
Process32Next
CloseHandle
Beep
lstrcmpiA
CreateProcessA
MultiByteToWideChar
GlobalAlloc
GlobalFree
GlobalLock
Process32First
GetLocaleInfoA
LoadLibraryA
QueryPerformanceFrequency
GetProcAddress
FreeLibrary
QueryPerformanceCounter
SetUnhandledExceptionFilter
GetModuleHandleW
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
SetConsoleTextAttribute
GetCurrentThreadId
GlobalUnlock
WideCharToMultiByte
USER32.dll TranslateMessage
UpdateWindow
GetKeyState
LoadCursorA
ScreenToClient
ClientToScreen
GetKeyboardLayout
GetForegroundWindow
SetCursor
GetClientRect
SetCursorPos
OpenClipboard
SetLayeredWindowAttributes
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetWindowLongA
DispatchMessageA
SetWindowPos
GetSystemMetrics
ShowWindow
GetAsyncKeyState
SetWindowLongA
FindWindowA
SetMenu
PeekMessageA
MessageBoxA
GetCursorPos
SHELL32.dll ShellExecuteA
ole32.dll CoInitialize
MSVCP140.dll ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?good@ios_base@std@@QEBA_NXZ
_Query_perf_frequency
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exception@std@@YA_NXZ
?_Xlength_error@std@@YAXPEBD@Z
_Query_perf_counter
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
IMM32.dll ImmSetCandidateWindow
ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
D3DCOMPILER_47.dll D3DCompile
VCRUNTIME140_1.dll __CxxFrameHandler4
VCRUNTIME140.dll memchr
memcmp
memcpy
memmove
__std_exception_copy
strstr
__current_exception_context
__C_specific_handler
_CxxThrowException
__std_exception_destroy
memset
__current_exception
__std_terminate
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__stdio_common_vsscanf
_wfopen
fwrite
fclose
fflush
fread
__stdio_common_vsprintf
fseek
_set_fmode
__stdio_common_vfprintf
__stdio_common_vsprintf_s
ftell
api-ms-win-crt-heap-l1-1-0.dll malloc
_set_new_mode
_callnewh
free
api-ms-win-crt-string-l1-1-0.dll strlen
strncmp
strncpy
strcmp
api-ms-win-crt-filesystem-l1-1-0.dll remove
api-ms-win-crt-runtime-l1-1-0.dll _get_initial_narrow_environment
_initterm
_initterm_e
exit
_exit
system
__p___argc
__p___argv
_c_exit
_register_thread_local_exe_atexit_callback
_seh_filter_exe
_cexit
terminate
_configure_narrow_argv
_crt_atexit
_initialize_narrow_environment
_set_app_type
_initialize_onexit_table
_register_onexit_function
api-ms-win-crt-math-l1-1-0.dll acosf
asin
atan
logf
atan2
atanf
powf
sin
sinf
sqrt
sqrtf
ceilf
cos
tanf
fmodf
cosf
__setusermatherr
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x17d
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.91161
MD5 1e4a89b11eae0fcf8bb5fdd5ec3b6f61
SHA1 4260284ce14278c397aaf6f389c1609b0ab0ce51
SHA256 4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df
SHA3 4bb9e8b5a714cae82782f3831cc2d45f4bf4a50a755fe584d2d1893129d68353

Version Info

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Jun-15 02:29:20
Version 0.0
SizeofData 892
AddressOfRawData 0x5e7f8
PointerToRawData 0x5d1f8

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Jun-15 02:29:20
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14005eb98
EndAddressOfRawData 0x14005eba0
AddressOfIndex 0x14009ac60
AddressOfCallbacks 0x140054650
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140066040

RICH Header

XOR Key 0x94bf4095
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 18
ASM objects (35721) 4
C objects (35721) 10
C++ objects (35721) 31
Imports (35721) 6
Imports (35215) 21
Total imports 248
C++ objects (LTCG) (36247) 9
Resource objects (36247) 1
Linker (36247) 1

Errors

Leave a comment

No comments yet.